FomoPeek Malware Exposes Users to iOS Kernel Exploit
A recent investigation by SlowMist has uncovered malicious code in FomoPeek versions 1.1-1.2, which could expose private keys, seed phrases, credentials, and files.
The security company found that the app contains an iOS kernel exploitation framework with eight different exploit methods, including one that can bypass the application sandbox.
The framework can automatically choose an attack approach based on the device model and iOS version. It has access to and decryption capabilities for Keychain and can read other files from installed applications.
SlowMist linked these malicious features to several reports of stolen user assets, including private keys being exposed. The investigation suggests that older versions of iOS may be more vulnerable.